First published: Wed Nov 13 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the Local Management Interface (LMI) in IBM Security Network Protection on XGS 5100 devices with firmware 5.1 before 5.1.0.6 and 5.1.1 before 5.1.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Network Protection | =5.1 | |
IBM Security Network Protection | =5.1.1 | |
IBM Security Network Protection 5100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5442 is classified as a Medium severity cross-site scripting (XSS) vulnerability.
CVE-2013-5442 affects IBM Security Network Protection on XGS 5100 devices with specific firmware versions.
You can identify a vulnerability to CVE-2013-5442 by checking if your firmware version is earlier than 5.1.0.6 or 5.1.1.1.
To fix CVE-2013-5442, upgrade your firmware to the latest versions 5.1.0.6 or 5.1.1.1 or later.
Yes, CVE-2013-5442 allows remote attackers to inject arbitrary web scripts or HTML into the affected device.